PSA for @openclaw contributors - there's a phishing campaign targeting us right now.
Got a GitHub notification this morning: "5000 $CLAW token allocation approved." Looked legit - came through GitHub's actual email system.
- The repo (Signalnyastrainer/OpenClawNetwork) doesn't exist — 404
- The user profile — 404
- The "claim" link is a wallet drainer disguised behind a https://t.co/xIDjZYIA6Y URL
- The "eligible members" list mixes real contributor usernames with bot accounts
they create a real GitHub Discussion, tag actual contributors by username, then nuke the repo after the notification emails go out. The email looks authentic because it did come from GitHub's infrastructure.
If you contribute to OpenClaw and got one of these - don't click anything. Delete it!
Grok Build is now available in Beta for all SuperGrok and X Premium+ users.
Use Plan Mode, create images and videos with Imagine, and build automations or orchestrators with the CLI.
Visit https://t.co/bpTHpjivWD to get started.
10 WEBSITES EVERY INTERNET USER SHOULD CHECK TONIGHT.
Bookmark all of them. Most people don't know half of these exist.
1. https://t.co/zwR28T6wZa
Shows every data breach your email is in and what got leaked.
2. https://t.co/3c9sMcOYLH
Shows every social profile, photo, and login tied to an email address.
3. https://t.co/MOsvtupjHn
Free disposable email for any signup you don't trust.
4. https://t.co/t6W6t9kzvQ
Burner inbox that self-destructs in 10 minutes.
5. https://t.co/lHWq4ZeJXH
A directory of direct links to delete your account from any major service.
6. https://t.co/vpVXkaS6Uc
Check if your face was used to train AI image models without consent.
7. https://t.co/cC7q3S3Uui
Tells you if your VPN is actually hiding your real location or leaking it.
8. https://t.co/1Q31VRhSQ6
Shows how trackable your browser fingerprint is, even in incognito mode.
9. https://t.co/TVtBWcv6Sw
Tells you which programs on your PC are useless bloatware or spyware.
10. https://t.co/yvtYh3ade9
Drop any file or link. It scans against 70+ antivirus engines instantly.
The internet is hostile by default. These websites are your free defense.
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
OpenClaw just plugged into X, and now your own hardware gets the claws. 🦞
Bring your Grok, SuperGrok or X Premium subscription to your OpenClaw agent.
Now even your personal agent is red-pilled and based.
Get Grokked:
https://t.co/pIj2vp1IpM
a prompt I've been using a lot recently:
implement <SPEC> and while you do, keep a running implementation-notes.html file (or markdown) with decisions you had to make weren't in the spec, things you had to change, tradeoffs you had to make or anything else I should know
Effective today, we are:
1) Doubling Claude Code’s 5-hour rate limits for Pro, Max, and Team plans;
2) Removing the peak hours limit reduction on Claude Code for Pro and Max plans; and
3) Substantially raising our API rate limits for Opus models.
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly.
A Vercel employee got compromised via the breach of an AI platform customer called https://t.co/7PY6gGtzgI that he was using. The details are being fully investigated.
Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments.
Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration.
We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel.
At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community.
The recommendation for all Vercel customers is to follow the Security Bulletin closely (https://t.co/BLVnic9fJC). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.
In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback.
We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance.
It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.